VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

29031 CVEsRSS

CVE-2026-11928Critical· 9.8
2w ago

IBM Verify Identity Access is vulnerable to a buffer overflow attack.

IBM Verify Identity Access is vulnerable to a buffer overflow attack.

▾ MidnightIBM · Verify Identity AccessEPSS 0.29%via NVD
CVE-2026-11929High· 7.5
2w ago

IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.

IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.

▾ TwilightIBM · Verify Identity AccessEPSS 0.16%via NVD
CVE-2026-11926High· 7.5
2w ago

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

▾ TwilightIBM · Verify Identity AccessEPSS 0.31%via NVD
CVE-2026-53459Critical· 9.3
2w ago

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Starting in version 0.1.6 and prior to version 0.2.4.4, a fail-open in the authentication code allows any attacker to bypass authentication by flood…

▾ Midnightmaziggy · bambuddyEPSS 0.76%via NVD
CVE-2026-11927Medium· 6.5
2w ago

IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services.

IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services.

▾ SunlitIBM · Verify Identity AccessEPSS 0.17%via NVD
CVE-2026-39038Medium· 6.1PoC
2w ago

BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (trufflebox-ui) in GenericNumerixTable.jsx.

BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (trufflebox-ui) in GenericNumerixTable.jsx.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-11921Critical· 9.1
2w ago

IBM Verify Identity Access containers may not apply management password change operations correctly.

IBM Verify Identity Access containers may not apply management password change operations correctly.

▾ MidnightIBM · Verify Identity AccessEPSS 0.23%via NVD
CVE-2026-11918Medium· 5.4
2w ago

IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mechanisms due to incomplete recursive inspection of nested payload content.

IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mechanisms due to incomplete recursive inspection of nested payload content.

▾ SunlitIBM · ContextForge MCP GatewayEPSS 0.16%via NVD
CVE-2026-81898High· 7.5
2w ago

In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in Express association views

In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in Express association views. A user able to submit an Address attribute could execute script in the sess…

▾ TwilightConcrete CMS · Concrete CMSEPSS 0.44%via NVD
CVE-2026-39039Medium· 5.3
2w ago

In BharatMLStack up to and including v1.3.0, Trufflebox UI stores the JWT authentication token, full user object, and session ID in the browser's localStorage, which is fully accessible to any JavaScript running on the page.

In BharatMLStack up to and including v1.3.0, Trufflebox UI stores the JWT authentication token, full user object, and session ID in the browser's localStorage, which is fully accessible to any JavaScript running on the page.

▾ SunlitEPSS 0.37%via NVD
CVE-2026-11864Medium· 6.5
2w ago

IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vuln…

IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vuln…

▾ SunlitIBM · Cloud Pak for Business AutomationEPSS 0.22%via NVD
CVE-2026-39040Medium· 5.4
2w ago

BharatMLStack up to and including 1.3.0 is vulnerable to Cross Site Scripting (XSS) via the component Trufflebox UI (trufflebox-ui) in ExpressionViewModal.jsx.

BharatMLStack up to and including 1.3.0 is vulnerable to Cross Site Scripting (XSS) via the component Trufflebox UI (trufflebox-ui) in ExpressionViewModal.jsx.

▾ SunlitEPSS 0.24%via NVD
CVE-2026-11729High· 8.5
2w ago

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to …

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to …

▾ TwilightIBM · MQEPSS 0.31%via NVD
CVE-2026-12358High· 7.5
2w ago

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

▾ TwilightIBM · Verify Identity AccessEPSS 0.39%via NVD
CVE-2026-18113High· 7.5
2w ago

In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing them into the page, so a user who could create or rename pages could store a script through a child page name and hav…

In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing them into the page, so a user who could create or rename pages could store a script through a child page name and hav…

▾ TwilightConcrete CMS · Concrete CMSEPSS 0.29%via NVD
CVE-2026-12742Medium· 5.4
2w ago

IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls.

IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls.

▾ SunlitIBM · Business Automation Workflow containers and traditionalEPSS 0.17%via NVD
CVE-2026-91855Medium· 5.3PoC
2w ago

A security flaw has been discovered in Open5GS up to 2.7.7

A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality of the file lib/pfcp/handler.c of the component PFCP Message Handler. Performing a manipulation results in denial of s…

▾ TwilightEPSS 0.72%via NVD
CVE-2026-89026Critical· 9.8PoC
2w ago

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticate…

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticate…

▾ AbyssalIssabel Foundation · Issabel FrameworkEPSS 0.69%via NVD
CVE-2026-81897Medium· 5.4⚖ disputed
2w ago

In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not validate the anti-CSRF token

In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not validate the anti-CSRF token. By causing an authenticated administrator to submit a forged cross-site request, a remote a…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.17%via NVD
CVE-2026-81896Medium· 5.4⚖ disputed
2w ago

Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Form block question labels when rendering them as column headers in the Dashboard Form Submissions report (concrete/single_pages/dashboard/reports/forms/legacy…

Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Form block question labels when rendering them as column headers in the Dashboard Form Submissions report (concrete/single_pages/dashboard/reports/forms/legacy…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-81895High· 7.2
2w ago

In Concrete CMS before 9.5.3, the Document Library block stored the file-set identifiers submitted through fsID[] without validating them as integers, and when the block was configured with setMode set to any it concatenated each stored …

In Concrete CMS before 9.5.3, the Document Library block stored the file-set identifiers submitted through fsID[] without validating them as integers, and when the block was configured with setMode set to any it concatenated each stored …

▾ Twilightconcretecms · concrete_cmsEPSS 0.51%via NVD
CVE-2026-81894Medium· 5.4⚖ disputed
2w ago

Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-image Caption field because the bundled Magnific Popup lightbox script (concrete/js/features/imagery/frontend.js) re-pa…

Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-image Caption field because the bundled Magnific Popup lightbox script (concrete/js/features/imagery/frontend.js) re-pa…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-63443High· 8.3
2w ago

Coder allows organizations to provision remote development environments via Terraform

Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected…

▾ Twilightcoder · coderEPSS 0.76%via NVD
CVE-2026-58201High· 8.7
2w ago

Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services

Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2, the Lokka-Microsoft tool in src/mcp/src/main.ts uses direct URL string concatenation to append the user-controlled …

▾ Twilightmerill · lokkaEPSS 0.48%via NVD
CVE-2026-21588High· 7.1
2w ago

This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, wit…

This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, wit…

▾ TwilightAtlassian · Confluence Data CenterEPSS 0.29%via NVD
CVE-2026-21587High· 7.1
2w ago

This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center

This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to…

▾ TwilightAtlassian · Jira Service Management Data CenterEPSS 0.32%via NVD
CVE-2026-21586High· 7.1
2w ago

This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Improper Authorizatio…

This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Improper Authorizatio…

▾ TwilightAtlassian · Confluence Data CenterEPSS 0.32%via NVD
CVE-2026-18111High· 8.5
2w ago

Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image, and Image blocks and before Concrete 8.5.21 in the feature and Image blocks because the external link URL was insuf…

Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image, and Image blocks and before Concrete 8.5.21 in the feature and Image blocks because the external link URL was insuf…

▾ TwilightConcrete CMS · Concrete CMSEPSS 0.34%via NVD
CVE-2026-18110High· 7.5PoC
2w ago

Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint (/ccm/system/user/autocomplete), which backs the "Preview as User" panel and other user-selector components

Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint (/ccm/system/user/autocomplete), which backs the "Preview as User" panel and other user-selector components. The endp…

▾ Midnightconcretecms · concrete_cmsEPSS 0.27%via NVD
CVE-2024-58385Critical· 9.8PoC
2w ago

Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL querie…

Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL querie…

▾ AbyssalYonyou · U8 CRMEPSS 0.38%via NVD
CVEs tagged “nvd” — page 278 · VulnSea